Remix.run Logo
microtonal 2 hours ago

It sounds like he did give them the password, but it was the password to wiping his phone and not unlocking it. I'm surprised they didn't back up the device first.

The duress password does not wipe the phone. It wipes the encryption keys from the secure element. The phone's storage is the backup, but it is worthless, unless law enforcement has an attack against AES that does not require a brute force attack (unlikely).

Dylan16807 2 hours ago | parent [-]

Oh please. That's not a real distinction. The phone as a unit, flash plus enabling chips, is wiped in an unrecoverable way.

And the primary copy is not a backup.

microtonal 21 minutes ago | parent | next [-]

This site is called Hacker News :), people might just want to learn how it works technically, so I think it is worth mentioning technical differences.

Also, it does make a small difference in practice. Erasing keys is pretty much immediate, while erasing storage can take some time (especially for phones with larger storage), so the attacker could still try to power down the device in some way to avoid all storage gets wiped.

inigyou 37 minutes ago | parent | prev [-]

It might be a real legal distinction, but probably not.